CVE-2023-4053: Full screen notification obscured by external program
A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-4573
- CVE-2023-4574
- CVE-2023-4575
- CVE-2023-4576
- CVE-2023-4577
- CVE-2023-4051
- CVE-2023-4578
- CVE-2023-4053
- CVE-2023-4580
- CVE-2023-4581
- CVE-2023-4582
- CVE-2023-4583
- CVE-2023-4584
- CVE-2023-4585
- CVE-2023-4045
- CVE-2023-4046
- CVE-2023-4047
- CVE-2023-4048
- CVE-2023-4049
- CVE-2023-4050
- CVE-2023-4052
- CVE-2023-4054
- CVE-2023-4055
- CVE-2023-4056
- CVE-2023-4057
- CVE-2023-4058
Frequently Asked Questions
What is the severity of CVE-2023-4053?
The severity of CVE-2023-4053 is medium.
Which software is affected by CVE-2023-4053?
Firefox < 116, Firefox ESR < 115.2, and Thunderbird < 115.2 are affected by CVE-2023-4053.
How can an attacker exploit CVE-2023-4053?
An attacker can exploit CVE-2023-4053 by using a URL with a scheme handled by an external program to obscure the full screen notification, leading to user confusion and possible spoofing attacks.
What is the remedy for CVE-2023-4053 in Firefox?
Upgrade Firefox to version 116 or higher to fix CVE-2023-4053.
What is the remedy for CVE-2023-4053 in Thunderbird?
Upgrade Thunderbird to version 115.2 or higher to fix CVE-2023-4053.